Standalone DFDSS

2019-10-18 Thread Donald J
Question is about generating an interrupt on a console for a standalone restore. I read this previous post: https://groups.google.com/forum/#!topic/bit.listserv.ibm-main/lX4ZGaoUH_s So for a z13 would the interrupt needed be the one described in zEnterprise System Support Element Operations Guide

Re: Standalone DFDSS

2019-10-19 Thread Donald J
Thanks Jim & Brian We have Visara which seems to not be working. Ticket is open on it. > Sent: Saturday, October 19, 2019 at 1:08 AM > From: "Brian Westerman" > To: IBM-MAIN@LISTSERV.UA.EDU > Subject: Re: Standalone DFDSS > > Jim is correct, all it takes is for one of the consoles that is attache

Re: Standalone DFDSS

2019-10-21 Thread Donald J
gt; Ken Mazer > This Cranky Systems Programmer says “Share your knowledge, others may find it > useful” > > > -Original Message- > From: IBM Mainframe Discussion List On Behalf Of > Donald J > Sent: Saturday, October 19, 2019 9:26 AM > To: IBM-MAIN@LISTSERV.UA.EDU > Subj

Re: Strange HMC issue

2015-11-23 Thread Donald J.
Select the Network Diagnostics icon from both your HMC and SE and then click on the menu bar TCP option to display all socket connections. -- Donald J. dona...@4email.net On Fri, Nov 20, 2015, at 09:00 PM, Tony Thigpen wrote: > Background: HMC software version 2.11.1 connected to a

Re: Strange HMC issue

2015-11-23 Thread Donald J.
There is also same option for the SE TCP menu item. BMC is probably the Baseboard Management Controller. You could check the bios and see if there is an option to turn DHCP on/off on the BMC. -- Donald J. dona...@4email.net On Mon, Nov 23, 2015, at 06:27 AM, Tony Thigpen wrote

Re: Where's Java!? (SMP/E needs to know.)

2016-01-21 Thread Donald J.
4 which is less desirable than the above. -- Donald J. dona...@4email.net On Thu, Jan 21, 2016, at 05:06 AM, David Crayford wrote: > > I also manage manually with generic symlinks. I do this for Apache > > webserver as well. > > Why? I'm interested why you woul

Re: System check stopped state - what is it?

2016-01-22 Thread Donald J.
to the IPL diagnostic area. Add X'28' to the address in X'14', and also read this as a real address in central storage. The result is the 31-bit virtual address of the IPL vector table (IVT). -- Donald J. dona...@4email.net On Fri, Jan 22, 2016, at 06:35 AM, R.S. wrote: > I t

Re: XML: Optimized Schema Representation (OSR) file generation

2016-01-29 Thread Donald J.
* cd /u/appl/xsd xsdosrg -v -o IRS.osr IRS-EXT-ACA-AIR-7.0.xsd -- Donald J. dona...@4email.net On Fri, Jan 29, 2016, at 12:23 PM, Zierdt, Richard A (IS) wrote: > IBM-Main is not the likely forum for this - an

Re: XML: Optimized Schema Representation (OSR) file generation

2016-02-03 Thread Donald J.
/u/appl/xsd is simply a user folder for user xsd files. xsdosrg binary is in /bin The OUTFILE and INFILE were obviously not needed either. They were used for additional STDIN input commands for co:z hybrid batch processing which I did not list. -- Donald J. dona...@4email.net

Re: (External):Re: IBM secure z/OS software delivery: Don't get locked out!

2016-03-11 Thread Donald J.
CA i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority 3 s:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority -- Donald J. dona...@4email.net On Thu, Mar 10, 2016, at 06:45 AM, Jousma, David wrote: > I had to come up wi

Re: (External):Re: IBM secure z/OS software delivery: Don't get locked out!

2016-03-11 Thread Donald J.
You need RemotePortRangeRef for port 21. Port 21 is remote. -- Donald J. dona...@4email.net On Fri, Mar 11, 2016, at 12:21 PM, Gibney, David Allen wrote: > Actually, I do: > TTLSRule ftp_c

Re: (External):Re: IBM secure z/OS software delivery: Don't get locked out!

2016-03-11 Thread Donald J.
ious if IBM has tested that mode? Can you confirm? -- Donald J. dona...@4email.net On Fri, Mar 11, 2016, at 01:56 PM, Kurt Quackenbush wrote: > > Their server also seems to require use of the CCC subcommand to clear the > > command channel. > > To be clear, IBM's serv

Re: PLEASE HELP TLS 1.2

2016-03-24 Thread Donald J.
Allows the use of TLS v1.0 (this is the default). ENCRYPTION=SSLV3 Allows the use of TLS v1.0 and SSL V3.0. -- Donald J. dona...@4email.net On Thu, Mar 24, 2016, at 08:37 AM, Lopez, Sharon wrote: > A federal agency changed to TLS v1.2 over the weekend

Re: PLEASE HELP TLS 1.2

2016-03-24 Thread Donald J.
he is on CICS 5.2, not 5.3. -- Donald J. dona...@4email.net On Thu, Mar 24, 2016, at 09:16 AM, McCabe, Ron wrote: > IBM would prefer that you use MINTLSLEVEL... > > The ENCRYPTION system initialization parameter has been deprecated. Use the > MINTLSLEVEL system initializati

Re: Apache Web Server running on z/OS unable to detect TLS 1.2

2016-03-29 Thread Donald J.
Try SSLProtocolEnable TLSv12 instead of TLSv1.2 You can test with an openssl command similar to: openssl s_client -connect 12.34.56.78:443 -tls1_2 -- Donald J. dona...@4email.net On Tue, Mar 29, 2016, at 02:26 PM, Jasi Grewal wrote: > Greetings, We are using Apache Web Server on z/OS sys

Re: Apache Web Server running on z/OS unable to detect TLS 1.2

2016-03-30 Thread Donald J
>...and I tried with Donald suggestion and unfortunately it did not worked. Post the output from the openssl s_client command. -- For IBM-MAIN subscribe / signoff / archive access instructions, send email to lists...@listserv.ua.e

Re: New to Z/OSMF - SOLVED

2016-04-05 Thread Donald J.
Great. Now the difficult part begins - figuring out how to use it. I think the recommended procedure for the old method was to create a base config with no plugins, then add the plugins by running izusetup again with the -add parameter, and A values in your override file. -- Donald J

Re: Looking for mainframe shops Lexington/Cincinnati

2017-08-28 Thread Donald J
Toyota used to be in Georgetown KY. WPAFB used to hire a lot of mainframe contractors. There are also a couple of insurance companies in Cincinnati. Cincinnati bell possibly. State of KY might have a mainframe in Frankfort. There is a federal site in Fort Knox with mainframes, might be Army.    

Re: Looking for mainframe shops Lexington/Cincinnati

2017-08-31 Thread Donald J
>I have also heard that there is an old system at University of Kentucky >Medical Center I had a phone interview with them about 6 years ago. They were making all there IT employees "re-apply" for their current positions and compete with outsiders for their positions.   I have never heard of that

Re: zAware?

2017-09-08 Thread Donald J
We are continuing to use the zAware LPAR and its data, but not much with the zAware app. I download the zAware data to my laptop, manipulate and filter it with scripts, and output it to an updated web page every 10 minutes.   Sent: Friday, September 08, 2017 at 2:44 AM From: "Styles, Andy (ITS z

Re: What cryptographic algorithm is not supported?

2017-11-08 Thread Donald J
I notice your cert display did not list a "Key Usage" section. X509v3 Key Usage: critical Digital Signature, Key Encipherment, Data Encipherment Digital Signature and Data Encipherment are defaults, but KeY Encipherment does not default and needs to be specified in Key Usage. X

Re: TCP/IP SSL trace help please xposted to IBMMAIN

2016-11-16 Thread Donald J.
try tracing the batch job name. your job is a client which does not use your ftp server, it uses the ibm smp ftp server. -- Donald J. dona...@4email.net On Wed, Nov 16, 2016, at 11:19 AM, Ward, Mike S wrote: > Hello all, we are having a little FTPS problem. As you can see below we

Re: LDAP on z/os

2016-11-17 Thread Donald J.
h non-RACF passwords in a separate ITDS backend. And configure it as you please. -- Donald J. dona...@4email.net On Thu, Nov 17, 2016, at 01:44 AM, venkat kulkarni wrote: > We need LDAP for two user id authentication purpose. Do we have any way to > implement this change > > On Nov 17

Re: Sftp implementation

2016-11-18 Thread Donald J.
psftp is an sftp client available with the putty download. -- Donald J. dona...@4email.net On Fri, Nov 18, 2016, at 02:09 AM, venkat kulkarni wrote: > Hello, > > We are doing sftp implementation but I am not able to find way to test this > scenarios. For ftp, i can test usin

Re: [EXTERNAL] Re: z/OS Web Based Dropbox ?

2016-11-30 Thread Donald J.
type: text/html" #-trace /u/curl/curlhttp.trace.log -- Donald J. dona...@4email.net On Wed, Nov 30, 2016, at 08:16 AM, Dyck, Lionel B. (TRA) wrote: > Thank you - I'll pass that along as an option - was told ftp/sftp was no

Re: IBM Lays Out Plans to Hire 25,000 in U.S. Ahead of Trump Meeting

2016-12-14 Thread Donald J.
I tried to re-apply for an opening. Got to page 9 of the 10 page online form. It said something about if former employee, fill out item X. Unfortunately item X was not on that page, and hitting NEXT button asked again to complete item X. -- Donald J. dona...@4email.net On Tue, Dec 13

Re: Mainframe printer connectivity

2017-01-19 Thread Donald J.
http://www.support.xerox.com/support/xpaf/support/enus.html -- Donald J. dona...@4email.net On Wed, Jan 18, 2017, at 09:51 PM, venkat kulkarni wrote: > Hello Group, > > Currently we are using mainframe printer with bus and tag connectivity with > Xerox printer via prism har

SYSLOG/OPERLOG Keyword Search

2017-02-10 Thread Donald J.
What programs (free or IBM or other) are available for doing historical keyword searches against the SYSLOG or OPERLOG archives? ISPF or otherwise. -- Donald J. dona...@4email.net -- http://www.fastmail.com - Email service worth paying for. Try it for free

Re: SYSLOG/OPERLOG Keyword Search

2017-02-10 Thread Donald J.
keywords are then returned. -- Donald J. dona...@4email.net On Fri, Feb 10, 2017, at 06:36 AM, Lizette Koehler wrote: > So you can use (depending on level of z/OS) the SDSF REXX function. > REXX > DFSORT > SAS > CA EASYTRIEVE > CA EARL > SYNSORT > > And so

Re: SYSLOG/OPERLOG Keyword Search

2017-02-10 Thread Donald J.
Splunk looks very interesting. Too bad they don't support z/Linux. -- Donald J. dona...@4email.net On Fri, Feb 10, 2017, at 06:44 AM, Pew, Curtis G wrote: > On Feb 10, 2017, at 8:30 AM, Donald J. wrote: > > > > What programs (free or IBM or other) are available

z/OS PKI Services HostIDMapping format

2014-03-10 Thread Donald J.
]:30780C1C4C554845343438404D5653332E4350412E53544154452E54582E55530C1C4C554845343438406D7673332E6370612E 73746174652E74782E75730C1C6C756865343438404D5653332E4350412E53544154452E54582E55530C1C6C756865343438406D7673332E6370612E73746174652E74782E7573 -- Donald J. dona...@4email.net -- http://www.fastmail.fm - Email

Re: z/OS PKI Services HostIDMapping format

2014-03-10 Thread Donald J.
I have tried. I'm thinking maybe there is a bug in the client. -- Donald J. dona...@4email.net On Mon, Mar 10, 2014, at 11:57 AM, Phil Sidler wrote: > On Mon, 10 Mar 2014 08:59:55 -0700, Donald J. wrote: > > >Could someone who is using z/OS PKI Services for z

Re: z/OS PKI Services HostIDMapping format

2014-03-11 Thread Donald J.
r certificate with your userid? If so, then the HostIDMapping extension was not needed or used. On Mon, Mar 10, 2014, at 02:38 PM, Phil Sidler wrote: > On Mon, 10 Mar 2014 13:49:38 -0700, Donald J. wrote: > > >Yes, the script helps to identify some things. What appilcation was it >

Re: z/OS PKI Services HostIDMapping format

2014-03-11 Thread Donald J.
I now have an openssl config which produces the same hex code as your vbsscript for lengths less than 128. For length above 128 openssl produces a different length code for the SET (x'31') which is x'318184'. Your script produces x'31820184'. I will do some testing with CICS Web Services and FTP

Re: z/OS PKI Services HostIDMapping format

2014-03-12 Thread Donald J.
ation=true? I have a ticket open with IBM, but no response in almost a week. -- Donald J. dona...@4email.net On Tue, Mar 11, 2014, at 02:04 PM, Walt Farrell wrote: > On Tue, 11 Mar 2014 05:54:24 -0700, Donald J. wrote: > > >I am currently using openssl to create certificates fo

Re: z/OS PKI Services HostIDMapping format

2014-03-12 Thread Donald J.
SECURE_LOGIN REQUIRED SECURE_PASSWORD OPTIONAL SECURE_CTRLCONN PRIVATE SECURE_DATACONN PRIVATE SECURE_FTP REQUIRED It works when the certificate is associated to a userid. -- Donald J. dona...@4email.net On Wed, Mar 12, 2014, at 10:53 AM, Phil Sidler wrote: > On

Re: z/OS PKI Services HostIDMapping format

2014-03-13 Thread Donald J.
CLASS NAME - SERVAUTH IRR.HOST.MVS3.domain.removed USER ACCESS ACCESS COUNT -- -- - RDZRSEDREAD00 FTPSERV2 READ00 > > But I could > >not get HostID

Re: z/OS PKI Services HostIDMapping format

2014-03-19 Thread Donald J.
I have a ticket open with the RDz client issues. IBM hasn't provided a resolution yet. They have been questioning the validity of my certificates, but now that they work on CICS Web Services that issue should not be questioned. > > All I can think of then is that RACF isn't finding the matchi

Re: z/OS PKI Services HostIDMapping format

2014-05-06 Thread Donald J.
the mapping is the 1st entry in the set of hostIdMappings. A problem ticket is currently open on that issue. On Fri, Mar 14, 2014, at 06:30 AM, Phil Sidler wrote: > On Wed, 12 Mar 2014 10:55:35 -0700, Donald J. wrote: > > >It works when the certificate is associated to a userid

Re: z/OS FTPS Client & Linux FTP server

2014-05-07 Thread Donald J.
Make sure client and server have a common cipher. SSL_AES_128_SHA and SSL_AES_256_SHA are probably more commonly used than SSL_RC4_SHA. Make sure the linus root certificate is in your z/OS client keyring. -- Donald J. -- http://www.fastmail.fm - A no graphics, no pop-ups email service

Re: z/OS FTPS Client & Linux FTP server

2014-05-07 Thread Donald J.
racdcert id(userid) listring(ring.name) racdcert id(userid) connect(ring(ring.name) LABEL('GoDaddy Root Label') CERTAUTH usage(CERTAUTH) ) -- Donald J. On Wed, May 7, 2014, at 06:34 AM, Mark Pace wrote: > The cipher was one of my early problems. But I figured that one

Re: z/OS FTPS Client & Linux FTP server

2014-05-07 Thread Donald J.
trace to track down these problems. Are you using AT-TLS environment for the FTPS client ? -- Donald J. dona...@4email.net On Wed, May 7, 2014, at 07:38 AM, Mark Pace wrote: > Trying to turn on some DEBUG information > DEBUG FLO > > FC1003 authServer: secure_socket_init failed w

Re: z/OS FTPS Client & Linux FTP server

2014-05-07 Thread Donald J.
If you aren't using any client certs, it is easier to just use a RAC virtual keyring for CERTAUTH server authentication: KEYRING *AUTH*/* -- Donald J. dona...@4email.net On Wed, May 7, 2014, at 07:38 AM, Mark Pace wrote: > Trying to turn on some DEBUG information > DEBUG FLO

Re: z/OS FTPS Client & Linux FTP server

2014-05-07 Thread Donald J.
The DEFAULT YES would be used for a client certificate, not for a CERTAUTH entry. -- Donald J. > Digital ring information for user IBMUSER: > > Ring: >>FtpSecur< > Certificate Label Name Cert Owner

Re: z/OS FTPS Client & Linux FTP server

2014-05-07 Thread Donald J.
You did do a: SETROPTS RACLIST(DIGTCERT) REFRESH after last changing the keyring? What does the LISTRING show now? Does the userid submitting the batch job have any ICH408I errors in the log? -- Donald J. -- http://www.fastmail.fm - Send your email first class

Re: z/OS FTPS Client & Linux FTP server

2014-05-07 Thread Donald J.
You need to change that to DEFAULT NO. -- Donald J. dona...@4email.net On Wed, May 7, 2014, at 01:01 PM, Mark Pace wrote: > Yes, I did the digtcert refresh > Digital ring information for user IBMUSER: > >Ring: > >FtpSecur< >Certificate Label Nam

Re: z/OS FTPS Client & Linux FTP server

2014-05-08 Thread Donald J.
- Filezilla is not a good program to test with, as it appears to not do server cert authenticatation. It is better to use curl for windows or curl for z/OS. -- Donald J. dona...@4email.net On Wed, May 7, 2014, at 03:38 PM, Neubert, Kevin wrote: > Is the chain complete? Check trust and Issue

Re: z/OS FTPS Client & Linux FTP server

2014-05-08 Thread Donald J.
t. I would guess your linux file only has the server cert in it, and it needs the intermediate cert in it as well, and optionally the root cert. -- Donald J. dona...@4email.net On Thu, May 8, 2014, at 07:31 AM, Mark Pace wrote: > I assume it's complete - I don't see an obvious

Re: z/OS FTPS Client & Linux FTP server

2014-05-12 Thread Donald J.
You need ApplicationControlled On as well as SecondaryMap On. Issue this command to see your resultant config: pasearch -p TCPIP > tcpip.pagent.dat -- Donald J. dona...@4email.net > > TTLSEnvironmentAdvancedParms > > { > > SecondaryMap On -- h

Re: z/OS FTPS Client & Linux FTP server

2014-05-12 Thread Donald J.
https://certs.godaddy.com/anonymous/repository.pki -- Donald J. dona...@4email.net > FC2903 authServerAttls: ioctl() failed on SIOCTTLSCTL - EDC8121I > Connection > reset. (errno2=0x77B17343) > EZA2897I Authentication negotiation > failed > EZA1534I *** Control connection with 10.6

z/OS Performance Analyst Job Posting

2014-05-23 Thread Donald J.
Job Opportunities Create application here: http://agency.governmentjobs.com/cpatx/default.cfm Job #: 2W11.14 Job Title: zEnterprise Performance Analyst (REOPENED) State Classification Title: Systems Analyst V Salary: $64,200.00 - $82,200.00 Annually Location: Austin, TX (LBJ)

Re: SSH connectivity with OMVS

2014-05-23 Thread Donald J.
FUNCTION ) // ELSE //* //SSHD EXEC PGM=BPXBATCH,REGION=0M,TIME=NOLIMIT, // PARM='PGM /bin/sh -c /u/local/sbin/sshd.sh' //STDERR DD SYSOUT=* //* // ENDIF

Re: Policy Agent, AT-TLS, and Ciphersuites

2014-06-05 Thread Donald J.
Do you have Security Level 3 FMID (JCPT3D1) installed? -- Donald J. dona...@4email.net On Thu, Jun 5, 2014, at 07:53 AM, Frank Chu wrote: > Hello, > > I am trying to work out how to get the zOS 1.13 FTP client to connect to > a FTP server (a FileZilla Server on Windows) via FT

DR site CHPID TYPE=FC Console Question

2014-07-11 Thread Donald J.
Our z196 3174 consoles are defined on a TYPE=CNC escon chpid. We will be using a zEC12 at a DR site for testing. Can the console virtual devices on our IODF TYPE=CNC chpid be attached to DR site VM devices on a real TYPE=FC chpid? Will our chpid/devices vary online ok? -- Donald J. dona

Re: running ldapsearch via JVL

2014-08-06 Thread Donald J.
n/ldapsearch -h mvs6 -p 3289 -D cn=yyy -w zzz > -b "O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB" > "(objectclass=*)" ; > // > > -- > Donald J. > dona...@4email.ne

Re: running ldapsearch via JVL

2014-08-06 Thread Donald J.
Try typing the ldapsearch directly from an omvs command line. I usually use openldap on my pc for commands. An OMVS segment for your userid is probably a requirement. -- Donald J. dona...@4email.net On Wed, Aug 6, 2014, at 12:08 PM, Tim Brown wrote: > Thanks, I ran this, it got rc=0

SMF records for SYSOUT file

2014-08-20 Thread Donald J.
CTTH441.SDB1.JOB07555.D032.? SYSOUT -- Donald J. dona...@4email.net -- http://www.fastmail.fm - Does exactly what it says on the tin -- For IBM-MAIN subscribe / signoff / archive access instructions, send

Re: SMF records for SYSOUT file

2014-08-21 Thread Donald J.
e parameter setting value. It appears application level tracing would be required to diagnose the issue. -- Donald J. dona...@4email.net On Thu, Aug 21, 2014, at 02:39 AM, Elardus Engelbrecht wrote: > Barry Merrill wrote: > > >There is no separate SMF record written when data i

Re: SMF records for SYSOUT file

2014-08-21 Thread Donald J.
a VPS issue. -- Donald J. dona...@4email.net > >What type of setting are you referring to? > > Some possible settings, YMMV: vps parameters listed > All of the very best for you. > > Groete / Greetings

Re: java on Z maintenance level question

2014-08-28 Thread Donald J.
The first is SDK V6.0.0 and the second is SDK V6.0.1 Each has its own levels as described here: http://www-03.ibm.com/systems/z/os/zos/tools/java/services/j6servsum31.html -- Donald J. dona...@4email.net On Tue, Aug 26, 2014, at 12:05 PM, Pommier, Rex wrote: > Hi, > > I have a qu

Re: ldapchangepwd

2014-10-21 Thread Donald J.
This works for me: ldapsearch -h mvs7 -D racfid=jojo123,profiletype=user,cn=RACFSY7 -w oldpwd/newpwd -s base -b "" objectclass=* -- Donald J. dona...@4email.net On Tue, Oct 21, 2014, at 07:58 AM, Tim Brown wrote: > Attempting to use ldapchangepwd. Any idea what is

Re: ldapchangepwd

2014-10-21 Thread Donald J.
That would be your SUFFIX parameter value. -- Donald J. dona...@4email.net On Tue, Oct 21, 2014, at 01:30 PM, Tim Brown wrote: > Thanks , where is RACFSY7 referred to in DSCONFIG? > > -Original Message- > From: IBM Mainframe Discussion List [mailto:IBM-MAIN@LISTSER

Re: ldapchangepwd

2014-10-22 Thread Donald J.
mainframe only. -- Donald J. dona...@4email.net On Wed, Oct 22, 2014, at 04:23 AM, Tim Brown wrote: > This gets a 0 but the password is still the old one > > sh /bin/ldapsearch -h 127.0.0.1 -p 389 -s base > -w oldpwd > -n oldpwd

Basic JES3 Exit Question

2012-10-02 Thread Donald J.
I am new to JES3, and have a JES3 exit 45 to install/update for XPAF. After wading thru the manuals, they only say to copy to SYS1.SIATLIB. Is anything else required (other than LLA refresh)? Is a JES3 restart required? -- http://www.fastmail.fm - A fast, anti-spam email service. ---

z/OS 1.12 SSHD authentication failing

2012-10-10 Thread Donald J.
I am testing an SSHD server on a new z/OS 1.12 system. The connections are failing with following messages on the client side: debug1: Remote protocol version 2.0, remote software version OpenSSH_5.0. debug1: match: OpenSSH_5.0 pat OpenSSH*. debug1: Enabling com

Re: z/OS 1.12 SSHD authentication failing

2012-10-10 Thread Donald J.
We recently added SERVAUTH to prevent ftps access to OMVS files. But all is working fine on 1.11 LPARs. I don't see any RACF errors in SYSLOG. -- Donald J. dona...@4email.net On Wed, Oct 10, 2012, at 12:55 PM, Rob Schramm wrote: > I think you may be running up against a SER

Re: z/OS 1.12 SSHD authentication failing

2012-10-11 Thread Donald J.
Thanks for response. It appears the SCEERUN2 XPLINK members were put in MLPA instead of dynamic LPA (error message at IPL time because of PDS-E). The MLS messages were apparently not errors, just misleading as to where the problem was. -- Donald J. dona...@4email.net On Wed, Oct 10

Re: ldapchangepwd

2014-10-22 Thread Donald J.
You are not supplying valid bind credentials. Suggest you get any ldapsearch to work first using TESTUSER's bind credentials. Then the password can be changed with just the addition of /newpwd after the current password on the ldapsearch. -- Donald J. dona...@4email.net On Wed

Re: Cross Posted from CICS-l CICS Web Services and Digital Signatures

2014-10-28 Thread Donald J.
According to Share document "CICS Identity and Security" from Pittsburgh 2014, only sha1 is supported on outbound signature? Just curious, how did you determine the same required signature was not produced? -- Donald J. dona...@4email.net On Tue, Oct 28, 2014, at 11:34 AM, Wa

Re: PKI Services for z/OS

2014-10-31 Thread Donald J.
LDAP would be required if you want to check for revoked certificates from PAGENT or CICS. LDAP could be somewhere besides z/os though. -- Donald J. dona...@4email.net On Thu, Oct 30, 2014, at 12:18 PM, Dazzo, Matt wrote: > We are starting to look at certificate management, I was wonder

DB2 Forum

2015-03-08 Thread Donald J.
Can someone recommend a good DB2 Forum? The one at IBM developerWorks is not very active. As example, 17 of the last 25 questions have gone with 0 replies. 6 of those with only 1 reply. I do see an IDUG DB2-L forum. -- Donald J. dona...@4email.net -- http://www.fastmail.com - Does

Re: Alter TRUST status on a certificate

2015-04-22 Thread Donald J.
You misspelled websphere. Try this with a capital S and no space. Label must exactly match. racdcert CERTAUTH alter(label('WebSphereCA')) notrust -- Donald J. dona...@4email.net On Wed, Apr 22, 2015, at 06:08 AM, nitz-...@gmx.net wrote: > All, > > I am new to this c

Re: Co:z SFTP and Public/Private Key Authentication

2013-05-13 Thread Donald J.
Activate debug on both ends of connection. Here is my jcl to do that on the client side: //STEPNAME EXEC PGM=COZBATCH,REGION=0M, // PARM='ru=userid8 rh=host1.xyz.com' //STEPLIB DD DISP=SHR,DSN=UTIL.TCP.COZ.LOADLIB //STDOUT DD SYSOUT=* //STDERR DD

Re: X11 forwarding

2013-06-06 Thread Donald J.
} //class EmptyFrame1 -- Donald J. dona...@4email.net On Thu, Jun 6, 2013, at 07:42 AM, Mark Pace wrote: > I want to test X11 forwarding using SSH in Unix System Services. But I > can't find an executable X application like xclock. I find some sample > programs, but not a

Re: X11 forwarding

2013-06-07 Thread Donald J.
You will also have to compile the xauth c program. I don't think IBM supplies a binary for it. -- Donald J. dona...@4email.net On Fri, Jun 7, 2013, at 06:07 AM, Mark Pace wrote: > That was the problem. > Some other issues with deprecated APIs. Maybe if I look at the sample C &

Re: X11 forwarding

2013-06-07 Thread Donald J.
uhe338/xauth/output.log -- Donald J. dona...@4email.net On Fri, Jun 7, 2013, at 06:17 AM, Donald J. wrote: > You will also have to compile the xauth c program. > I don't think IBM supplies a binary for it. > > -- > Donald J. > dona...@4email.net > &g

Re: ZFS MountCall / Osi Wait

2013-06-17 Thread Donald J.
A writable zfs must be cleanly unmounted or there will be a 65 second delay at IPL time for each one. This can be avoided by mounting it on another system and then immediately unmounting it. See Share 2012 document "zFS Diagnosis II: Problem Determination and File System Monitoring". --

Re: X11 forwarding

2013-06-26 Thread Donald J.
Check x11DisplayOffset value. If should be set to something like 10 if you want to forward directly via port 6010, or set to 0 if you want to tunnel through your SSH port 22 connection. My DISPLAY is set to 127.0.0.1:0 and my x11DisplayOffset is 0. -- Donald J. dona...@4email.net On Wed

Re: SSH Performance

2013-07-11 Thread Donald J.
Mine from a SuSE linux to z/OS 1.13: real0m1.224s user0m0.008s sys 0m0.008s -- Donald J. dona...@4email.net > > > > From Solaris to MVS: > > > > 133$ time ssh user@MVS date > > Mon Jul 8 07:43:06 MDT 2013 > > > > re

Re: Is it possible to open PCOMM session up to 50?

2013-07-17 Thread Donald J.
>From each of the 25 PCOMM telnet sessions, you could logon TSO and enter TSO TELNET MVSxyz to create another 25 sessions. -- Donald J. dona...@4email.net On Wed, Jul 17, 2013, at 02:26 AM, Alex Wang wrote: > Hey, there. > > I'm curious about is it possible to open about

OMVS su -

2012-11-26 Thread Donald J.
doesn't want them changed to add a home. -- Donald J. dona...@4email.net -- http://www.fastmail.fm - Choose from over 50 domains or use your own -- For IBM-MAIN subscribe / signoff / archive access instructions, send em

Re: OMVS su -

2012-11-26 Thread Donald J.
No, that's doesn't do it. We have: BROWSESYS1.SY1.PARMLIB(BPXPRM00) - 01 Line 0180 Col 001 080 Command ===> Scroll ===> CSR SUPERUSER(BPXROOT) ---> su - /home/root ===> env

Re: OMVS su -

2012-11-27 Thread Donald J.
n su mode may be different. Admin utilities may not have permissions to run outside of su, but why have them in your path if you aren't going to run them. Someone pm'd me with a solution, so it is possible... -- Donald J. dona...@4email.net > > Why do you do a "su -&qu

Re: CHPID TYPE OSE Port 1 of OSA Express3

2012-12-03 Thread Donald J.
What is in your VTAM TRLE nodes? -- Donald J. dona...@4email.net On Mon, Dec 3, 2012, at 05:43 AM, Rebecca Martin wrote: > We are having problems using port 1 of our new OSA Express3 T1000 on a > z114 (4 ports with 2 PCHID). Running z/OS 1.12. The CHPID is defined as > TYPE=OSE.

Re: CHPID TYPE OSE Port 1 of OSA Express3

2012-12-03 Thread Donald J.
Correct. Examples for nonQDIO are in this share document: https://share.confex.com/share/117/webprogram/Session9295.html -- Donald J. dona...@4email.net On Mon, Dec 3, 2012, at 07:02 AM, Rebecca Martin wrote: > Donald, for LCS we have no VTAM definition only what is in the TCPIP > p

Re: Secure Service Delivery

2013-02-22 Thread Donald J.
> Instead of asking customers to spend a lot of time, money and grief on > certificates, isn't it about time we stop fighting the FTPS vs SFTP > battle? SFTP clearly prevails, Speaking of grief, ask a Cobol programmer to write to an OMVS Unix file. They need to add support for z/OS files before S

Re: Secure Service Delivery

2013-02-22 Thread Donald J.
I didn't say there was a problem. Our applicatons mgmt does not want to spend the time to train programmers on how to do it. I will check out the Dovetailed Tech mod recommended by John M. in the other post. Thanks, John, for the info. -- Donald J. dona...@4email.net On Fri, Feb 22,

Re: Secure Service Delivery

2013-02-22 Thread Donald J.
It also does not appear to support the chroot environment option. -- Donald J. dona...@4email.net On Fri, Feb 22, 2013, at 10:39 AM, Ed Gould wrote: > John: > > That may be fine for your shop but others need support in a > production environment. > > Ed > > On

Re: Secure Service Delivery

2013-02-25 Thread Donald J.
rver.sh" which appears to prevent use of chroot? I see no mention of chroot in the Co:z doc or forum. Is anyone using chroot with co:z? -- Donald J. dona...@4email.net On Fri, Feb 22, 2013, at 01:36 PM, John Gilmore wrote: > Donald J. wrote: > > | It also does not appear to su

Re: TN3270 I/P Access fails after IPL

2013-03-06 Thread Donald J.
Check that LP #'s are correct for each LPAR. Looks similar to this: http://bit.listserv.ibm-main.narkive.com/NJ8Hqmgn/osa -- Donald J. dona...@4email.net On Tue, Mar 5, 2013, at 01:43 PM, Tom Trainor wrote: > I have four(4) LPARS on a single CHPID for an Ethernet CHPID defined

Re: BPXBATCH copy to mvs-ds FSUM6259

2013-03-18 Thread Donald J.
Try putting a "sleep 2" after the cp. -- Donald J. dona...@4email.net On Fri, Mar 15, 2013, at 08:33 AM, Monika Amiss wrote: > Dear Group, > > I have a strange behavior. In the first step I call an Shellscript which > does a > cp /user/tmp.txt &

Re: BPXBATCH copy to mvs-ds FSUM6259

2013-03-18 Thread Donald J.
L.OMS.V420.OMS1.TEMSNOTE'" sleep 2 I still get the error on a very small percent of the time: cp: FSUM6259 target file "//'UTIL.OMS.V420.OMS1.TEMSNOTE'": EDC5061I An error occurred when attempting

Re: BPXBATCH copy to mvs-ds FSUM6259

2013-03-18 Thread Donald J.
l use the same .TEMSNOTE z/OS file. $mfile is a 1 line single record OMVS file. -- Donald J. dona...@4email.net On Mon, Mar 18, 2013, at 07:55 AM, Paul Gilmartin wrote: > On Mon, 18 Mar 2013 07:37:25 -0700, Donald J. wrote: > > >I was getting same error in a TEMS script I wrote. >

Re: SMTP question.

2016-04-28 Thread Donald J.
Does adding "NOSOURCEROUTE ENABLED" to your SMTP task config change anything? -- Donald J. dona...@4email.net On Wed, Apr 27, 2016, at 05:05 PM, Field, Alan wrote: > We run SMTP on one lpar (z/OS 2.1). > > Recently we switched our mail server from Notes to Exchange. >

Re: Java problem

2016-05-08 Thread Donald J.
Try doing your javac like below from your home directory. Then see if any useful info is in your file javac.log javac -J-Xverbosegclog:javac.log -J-XX:+PrintGCDetails -J-XX:+PrintGCTimeStamps -help -- Donald J. dona...@4email.net On Sat, May 7, 2016, at 08:25 AM, Phil Smith III wrote

Re: [EXTERNAL] Re: smp/e sha-2 support?

2016-05-17 Thread Donald J.
that, your IBM cert and the GeoTrust SSL CA - G3 cert will both be sha2. It is not significant that the GeoTrust Global CA root certificate is sha1. -- Donald J. dona...@4email.net On Tue, May 17, 2016, at 07:53 AM, John Eells wrote: > So...suppose we were to do something like this*: &g

Re: [EXTERNAL] Re: smp/e sha-2 support?

2016-05-17 Thread Donald J.
- 82 03 7d 30 82 02 e6 a0-03 02 01 02 02 03 12 bb ..}0 05f0 - e6 30 0d 06 09 2a 86 48-86 f7 0d 01 01 05 05 00 .0...*.H.... -- Donald J. dona...@4email.net On Tue, May 17, 2016, at 03:24 PM, Donald J. wrote: > John, > > I don't think you have the right GeoT

Re: [EXTERNAL] Re: smp/e sha-2 support?

2016-05-17 Thread Donald J.
Authority -- Donald J. dona...@4email.net On Tue, May 17, 2016, at 05:08 PM, Andrew Rowley wrote: > On 18/05/2016 0:53, John Eells wrote: > > - Added support for both SHA-2 (SHA-256) and 2048-bit RSA certificates.** > > - Put the package signing verification certificate wher

z/OS XL C/C++ Requirement

2016-06-02 Thread Donald J.
used the compiler on previous versions is to compile the XAUTH program, and it should be upward compatible for new releases. -- Donald J. dona...@4email.net -- http://www.fastmail.com - Does exactly what it says on the tin

Re: Mounting NFS Directory on zOS as Binary

2016-06-22 Thread Donald J.
after you get it working. Also do you have the host names defined in a host table or DNS server? -- Donald J. dona...@4email.net On Tue, Jun 21, 2016, at 01:47 PM, Jasi Grewal wrote: > Greetings, I am trying to mount this zLinux Filesystem on zOS using NFS with > the following comma

  1   2   >